Last seven days
- First activity
- Aug 14, 2026
- Last activity
- Aug 14, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
NightLedger is a Windows backdoor associated with the Iran-linked threat actor Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore.
Profile source: Mallory opens in a new tabNightLedger
NightLedger is a Windows backdoor associated with the Iran-linked threat actor Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. It has been used in long-term cyber-espionage operations targeting organizations across the Middle East and Africa, including entities in aerospace, aviation, defense, telecommunications, government, financial services, and small and medium-sized business environments.
NightLedger is designed for covert post-compromise access and operator tasking. It has been observed masquerading as a legitimate DLL and executing through DLL search-order hijacking alongside a trusted Windows binary, indicating deliberate tradecraft for stealth and execution. The malware communicates with command-and-control infrastructure over HTTPS and supports a broad set of remote-access and post-exploitation functions. Documented capabilities include host and user reconnaissance, directory and logical drive enumeration, process listing and management, arbitrary process execution, file upload and download, file copy and deletion, screenshot capture, DLL loading, beacon interval updates, and collection of Windows diagnostic logs including NetSetup.log. Its command parsing and overall design have been noted as similar to the TWOSTROKE backdoor previously linked to the same actor.
NightLedger has been reported as part of a broader Mirage Kitten intrusion set that also includes the BridgeHead and ArcBridge tunneling tools, which are used to relay traffic and maintain covert access through victim environments. In observed operations, the broader campaign relied on highly targeted spearphishing, including recruitment-themed lures and fake videoconferencing pages delivering malicious archives. The malware and surrounding tooling reflect victim-specific tailoring, operational security, and a sustained focus on intelligence collection rather than financially motivated activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
The centerpiece of the campaign is NightLedger, a newly identified Windows backdoor attributed to Mirage Kitten... Once loaded, NightLedger contacts its C2 infrastructure over HTTPS and supports a broad range of post-compromise activities including system reconnaissance, process execution, directory enumeration, screenshot capture, file upload and download, process management, and collection of Windows diagnostic logs such as NetSetup.log.
The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger... The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.